vendor:
Freefloat FTP Server
by:
Waqas Ahmed Farooqi
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: Freefloat FTP Server
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:freefloat:freefloat_ftp_server:1.0
Platforms Tested: Windows XP SP3
2023
Freefloat FTP Server 1.0 – ‘PWD’ Remote Buffer Overflow
The exploit allows an attacker to execute arbitrary code by sending a specially crafted 'PWD' command to the Freefloat FTP Server 1.0. It triggers a buffer overflow in the server, leading to remote code execution.
Mitigation:
The vendor has not released a patch or mitigation for this vulnerability. It is recommended to discontinue the use of Freefloat FTP Server 1.0 and switch to a more secure FTP server software.